PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-06-16 20:41
Updated : 2017-08-28 18:31
NVD link : CVE-2012-2417
Mitre link : CVE-2012-2417
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
dlitz
- pycrypto